On Wed, 16 Sep 2026, Brandon Martin via NANOG wrote:
On 9/16/26 18:08, Majdi S. Abbas wrote:
If the access technology you're using supports it, some form of mac locking/filtering your access customers is the usual way SPs handle unwanted traffic.
But how does one determine what MAC address to lock to? You can't lock to the first MAC you see. That could be something random on their LAN. You can't even lock to the first thing you see that sends a DHCP request for the same reason.
I thought I was the only one pulling my hair out with this. Calix has a feature that lets you limit a PON customer to a "single MAC at a time." Each time they do a DHCP request from another MAC and get a new IP, the Calix shelf will forge a DHCP release request as the previous IP/MAC seen from that customer. It at least limits the damage the customer can do (especially important in smaller subnets where one misconfigured customer can run the subnet out of IPs). It must be annoying as hell for the user, each device on their network essentially taking turns having Internet. ---------------------------------------------------------------------- Jon Lewis, MCP :) | I route Blue Stream Fiber, Sr. Neteng | therefore you are _________ http://www.lewis.org/~jlewis/pgp for PGP public key_________